Signature Verification Flaw in OpenSSL Encrypt Affects Security Protocols
CVE-2026-81700

9.3CRITICAL

Key Information:

Vendor

Jahlives

Vendor
CVE Published:
27 August 2026

What is CVE-2026-81700?

OpenSSL Encrypt versions before 1.4.9 contain a vulnerability in the signature verification process within gpg_runner.verify_detached. This flaw allows the acceptance of revoked and expired keys due to inadequate checks of VALIDSIG status. Attackers can leverage compromised keys, which have been revoked or expired, to bypass signature verification mechanisms. This could lead to the execution of malicious plugins, posing a serious threat to host processes.

Affected Version(s)

openssl_encrypt 0 < 1.4.9

openssl_encrypt 1.4.9

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.